5
CVSSv2

CVE-2010-3091

Published: 29/09/2010 Updated: 30/09/2010
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

The OpenID module in Drupal 6.x prior to 6.18, and the OpenID module 5.x prior to 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not verifying the openid.return_to value, which allows remote malicious users to bypass authentication by leveraging an assertion from an OpenID provider.

Vulnerable Product Search on Vulmon Subscribe to Product

drupal drupal 6.0

drupal drupal 6.3

drupal drupal 6.4

drupal drupal 6.5

drupal drupal 6.6

drupal drupal 6.11

drupal drupal 6.12

drupal drupal 6.13

drupal drupal 6.14

drupal drupal 6.1

drupal drupal 6.16

drupal drupal 6.2

drupal drupal 6.7

drupal drupal 6.9

drupal drupal 6.10

drupal drupal 6.15

drupal drupal 6.17

drupal drupal 6.8

peter wolanin openid 5.x-1.1

peter wolanin openid 5.x-1.2

peter wolanin openid 5.x-1.3

peter wolanin openid 5.x-1.x

peter wolanin openid 5.x-1.0

Vendor Advisories

Several vulnerabilities have been discovered in Drupal 6 a fully-featured content management framework The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2010-3091 Several issues have been discovered in the OpenID module that allows malicious access to user accounts CVE-2010-3092 The upload module includes a ...